Music

Privacy Policy

Effective date:

Lab86 Music is a service from Lab86. It is at music.lab86.io and playlist.jakoblangtry.com. It converts songs, albums, artists, and playlists between music services.

This policy tells you which data we collect, why we collect it, and what we do with it. It applies to the website, the API, and the iOS Shortcut. If you have a question, send an email to jakob@lab86.io.

Summary

  • You can convert links and share public playlists without an account.
  • We do not have user accounts. Our database has no record for each user.
  • When you connect a music service, we keep its tokens in a cookie in your browser. We do not keep them in our database.
  • We use the access that you give only for the tasks that you start.
  • We do not sell your data. We do not use it for ads. We do not use analytics or ad trackers.

Data that we collect and why

Links and search text

When you convert a link or search for a song, our server reads the link or text. It then searches the music services for the same item.

We keep a public record of each song, album, or artist that you convert: its title, artist name, and cover art address. We use this record to show a public page for the item and to put that page in our sitemap. The record does not identify you.

Shared playlists

When you make a share link, we copy the playlist into our database. The copy has the playlist name, cover art address, and source service. For each track, it has the title, artist, album, cover art address, ISRC code, and length.

The copy can also have the name of the playlist owner. If you share a playlist from your Spotify library, it has your Spotify display name.

A share link stops working 48 hours after you make it. We delete the copy when a person opens the expired link. Until then, an expired copy can stay in our database. To delete a copy before then, send an email to jakob@lab86.io.

Data from connected music services

When you connect a music service, we read only the data that is necessary for the task that you start. The next section tells you about each service.

Technical data

Our hosting provider gets standard technical data for each page that you open, such as your IP address and browser type. Our server writes error logs to find problems. Our code does not write your tokens to these logs.

Connected music services

You connect a service only when you want to convert or import a playlist in your own account. Spotify, Apple, Google, and TIDAL show you the permissions before you agree.

Spotify

You sign in with Spotify OAuth with PKCE. The permissions let us read your email address, your Spotify profile, and your private and collaborative playlists. They also let us change your public and private playlists.

We use this access to show your playlists and read their tracks. When you start a conversion, we make a new playlist and add tracks to it. We keep your Spotify user ID, display name, email address, profile image address, and tokens in the spotify_session cookie.

Apple Music

You connect Apple Music with Apple MusicKit JS. Apple gives your browser a Music User Token. We keep this token in the session storage of your browser. Your browser deletes it when you close the tab.

Your browser sends the token to our server with each Apple Music task. Our server uses it to read your library playlists and their tracks. When you start a conversion, it makes a new playlist and adds tracks to it. Our server does not keep this token.

YouTube (Google)

You connect YouTube with Google OAuth. We use one permission: https://www.googleapis.com/auth/youtube. Google shows this permission as access to manage your YouTube account.

We use this access only when you start a playlist import into YouTube. For that import, our server does these tasks:

  • It searches YouTube for a video for each track of the playlist.
  • It makes a new private playlist in your YouTube account.
  • It adds the videos that it found to that new playlist.

We do not read, change, or delete your other YouTube playlists, videos, or channel data. We do not get your name or email address from Google. We keep the Google access token and refresh token in the youtube_session cookie. We do not keep Google tokens or data from your YouTube account in our database.

When you share a public YouTube playlist, we read it with our own API key. We do not use your Google account for that task. We keep a copy of that public playlist with the same rules as other shared playlists. When you convert a YouTube link, we keep the public record that the section above tells you about.

TIDAL

You sign in with TIDAL OAuth 2.1 with PKCE. We use the user.read, playlists.read, and playlists.write permissions. We read the country of your account to find tracks that you can play. When you start a conversion, we make a new playlist and add tracks to it. We keep the tokens and your country code in the tidal_session cookie.

Deezer

We read public Deezer playlists and the Deezer catalog without your account. The Deezer account connection is optional, because Deezer has no official method for apps to change playlists.

If you paste your Deezer ARL, we check it with Deezer and keep it only in the deezer_arl cookie. An ARL gives full access to your Deezer account. Our server uses it only to make a new private playlist and add tracks to it when you start a conversion. This connection is not official and can be against the Deezer terms.

Amazon Music

We do not connect to your Amazon account. We only make links to Amazon Music search pages.

Google user data and YouTube API Services

Lab86 Music's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

The policy is at https://developers.google.com/terms/api-services-user-data-policy.

Lab86 Music uses YouTube API Services. When you connect YouTube to Lab86 Music, you agree to the YouTube Terms of Service at https://www.youtube.com/t/terms. The Google Privacy Policy at https://policies.google.com/privacy applies to the data that Google collects.

  • We use Google user data only for the YouTube import that you start.
  • We do not sell Google user data. We do not use it for ads.
  • We do not use Google user data to develop, improve, or train AI or machine learning models.
  • No person reads your Google user data, except with your permission, to keep the service safe, or when the law makes it necessary.

You can cancel our access to your Google account at any time at https://myaccount.google.com/permissions.

Who gets data

Music services

Spotify, Apple, Google (YouTube), TIDAL, and Deezer get the calls that our server makes for you. A call can contain your token for that service and the names of the tracks, artists, and playlists that you convert.

OpenRouter

Our server can use OpenRouter and the TypeSafe Jev model to select the correct recording of a track. When this function is on, our server sends track data to OpenRouter. The data is the title, artist, album, length, and ISRC code of the source track and of the candidate tracks.

For a YouTube import, the candidates are video titles and channel names from YouTube search results. We do not send tokens, account identifiers, or playlist names. Our server keeps the result in memory for one hour.

Railway

Railway hosts our website and server. Our PostgreSQL database keeps the shared playlist copies and the public link records.

Apple

Each page gets the Apple MusicKit JS library from Apple servers. Apple then gets your IP address and browser data. The Apple privacy policy applies to that data.

Image servers

Some pages show cover art directly from the image servers of the music services. Those servers get your IP address.

The law

We can share data when the law makes it necessary.

We do not sell or rent your data to any person or company.

Cookies and browser storage

We use cookies only to keep you connected to your music services and to make sign-in safe. We do not use cookies for ads or tracking. On our website, the cookies that hold tokens have the HttpOnly and Secure attributes. Scripts on the page cannot read them.

Service cookies

spotify_session, youtube_session, and tidal_session hold tokens for 30 days. deezer_arl holds your Deezer ARL for 180 days. When you disconnect a service, we delete its cookie.

Sign-in cookies

During sign-in, short cookies hold a security value, a PKCE code, and the page to return to. They expire after 10 minutes. We delete them when the sign-in is complete.

Session storage

Your Apple Music User Token. Your browser deletes it when you close the tab.

Local storage

Your last 10 link conversions and your light or dark theme. This data stays in your browser. We do not get it. Select Clear in the history list to delete your conversions.

Disconnect and deletion

  • To disconnect a service, select Disconnect for that service on the dashboard. This deletes the token from your browser.
  • Disconnect does not cancel the access at the service. To cancel Google access, go to https://myaccount.google.com/permissions. To cancel Spotify access, go to https://www.spotify.com/account/apps/. For other services, use the account page of that service.
  • To delete all cookies and browser storage for Lab86 Music, clear the site data in your browser.
  • To delete a shared playlist or other data, send an email to jakob@lab86.io. Tell us the share link or the data. We delete it and send you a reply.
  • We delete only the data that Lab86 Music keeps. We do not delete data in your music service accounts.
  • A playlist that we make for you in YouTube, Spotify, Apple Music, TIDAL, or Deezer stays in that account. To delete it, delete it in that service. For YouTube, go to YouTube or YouTube Music.

Security

Our website uses HTTPS. Cookies that hold tokens are HttpOnly. No method to send or keep data on the internet is fully safe. We cannot make sure that your data is always safe.

Children

Lab86 Music is not for children younger than 13. We do not knowingly collect data from children younger than 13. If you think that a child gave us data, send an email to jakob@lab86.io. We then delete the data.

Changes to this policy

We can change this policy. When we change it, we put the new effective date at the top of this page. If a change is important, we show a notice on the website.

Contact

Lab86 operates Lab86 Music. Send questions about this policy or your data to jakob@lab86.io.